Overview 21 indicators
Rancor is a threat group that has led targeted campaigns against the South East Asia region. Rancor uses politically-motivated lures to entice victims to open malicious documents.
| domain | 18 | G0075-domain.txt |
| url | 2 | G0075.json |
| ipv4 | 1 | G0075.json |
Techniques 9 ATT&CK
Open in ATT&CK Navigator → or download the layer (9 techniques, layer 4.5)
- T1053.005 Scheduled Task
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1071.001 Web Protocols
- T1105 Ingress Tool Transfer
- T1204.002 Malicious File
- T1218.007 Msiexec
- T1546.003 Windows Management Instrumentation Event Subscription
- T1566.001 Spearphishing Attachment
Software 4
Principal sources 8 reports
Ranked by how many of this actor's indicators each report brought in.
- 9research.checkpoint.com/rancor-the-year-of-the-phish
- 9otx.alienvault.com/pulse/5d94cb1196acaec6cb740e33
- 7unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-ea…
- 4unit42.paloaltonetworks.com/rancor-cyber-espionage-group-uses-new-c…
- 4otx.alienvault.com/pulse/5dfa52f208b44bd6293eb130
- 4virustotal.com/gui/ip-address/139.162.14.25/relations
- 1twitter.com/MeltX0R/status/1172046597942915072
- 1meltx0r.github.io/tech/2019/09/11/rancor-apt.html
Related groups 2
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 21 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
unit42.paloaltonetworks.com/rancor-cyber-espionage-group-uses-new-c… · otx.alienvault.com/pulse/5dfa52f208b44bd6293eb130 · virustotal.com/gui/ip-address/139.162.14.25/relations
domain bafunpda.xyz domain kfesv.xyz ipv4 139.162.14.25 url http://199.247.6.253 -
research.checkpoint.com/rancor-the-year-of-the-phish · otx.alienvault.com/pulse/5d94cb1196acaec6cb740e33
754d56-8523.sexidude.com charleseedwards.dynamic-dns.net dsdfdscxcv.justdied.com dsgsdgergrfv.toythieves.com kibistation.onmypc.net oui6473rf.xxuz.com sfstnksfcv.jungleheart.com -
unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-ea…
facebook-apps.com ftp.chinhphu.ddns.ms goole.authorizeddns.us jdanief.xyz microsoft.authorizeddns.us microsoft.https443.org msdns.otzo.com -
twitter.com/MeltX0R/status/1172046597942915072 · meltx0r.github.io/tech/2019/09/11/rancor-apt.html
http://167.71.237.100 -
research.checkpoint.com/rancor-the-year-of-the-phish · otx.alienvault.com/pulse/5d94cb1196acaec6cb740e33
vvcxvsdvx.dynamic-dns.net -
research.checkpoint.com/rancor-the-year-of-the-phish · otx.alienvault.com/pulse/5d94cb1196acaec6cb740e33
nicetiss54.lflink.com
Further reading 10
- attack.mitre.org/groups/G0075
- researchcenter.paloaltonetworks.com/2018/06/unit42-rancor-targeted-attacks-…
- meltx0r.github.io/tech/2019/09/11/rancor-apt.html
- otx.alienvault.com/pulse/5d94cb1196acaec6cb740e33
- unit42.paloaltonetworks.com/rancor-cyber-espionage-group-uses-new-c…
- twitter.com/MeltX0R/status/1172046597942915072
- unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-ea…
- otx.alienvault.com/pulse/5dfa52f208b44bd6293eb130
- virustotal.com/gui/ip-address/139.162.14.25/relations
- research.checkpoint.com/rancor-the-year-of-the-phish